How WP Foreman connects to your site

Signed requests, one-time keys, no stored passwords.

Updated Oct 9, 2026

WP Foreman never asks for your WordPress password, FTP or hosting login. The connection works with cryptographic signatures instead.

Pairing

  1. WP Foreman creates a one-time connection key for one site address. It expires in 24 hours and only a fingerprint of it is stored.
  2. When you paste it, the plugin creates its own key pair on your site and sends WP Foreman its public half. WP Foreman checks the key and the site’s address match, then destroys the key so it can’t be reused.
  3. WP Foreman sends back its own public key. From then on each side can check the other’s signature.

Every request is signed

  • Every command WP Foreman sends is signed with Ed25519 and includes the exact time and a one-time random value.
  • The plugin rejects anything with a bad signature, anything older than 5 minutes, and any request it has already seen. A captured request can’t be replayed.
  • Reports the plugin sends to WP Foreman are signed by the site’s own key in the same way.

Allowlisting WP Foreman

Every request WP Foreman sends to your websites carries the user agent WPForeman/1.0 (+https://wpforeman.com/docs/how-wp-foreman-connects/) and goes to /wp-json/wpforeman/v1/command (or ?rest_route= on sites without pretty permalinks), or to /wp-admin/admin-ajax.php?action=wpforeman_command for changes to plugin files on hosts that require wp-admin. If a firewall or host blocks these, allow that user agent on those paths. Requests are still checked for a valid signature by the plugin, so allowlisting them doesn’t let anyone else in. On WP Engine, see Websites on WP Engine for the rule to ask their support for.

Limits on what the plugin will do

  • It only answers a fixed list of commands.
  • It refuses any file path outside your WordPress folder.
  • Its private key stays on your site and is never sent anywhere.
Was this helpful?